Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.
2009-04-27T22:30:00.267
2025-04-09T00:30:58.490
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sun | jdk | ≤ 1.5.0 | Yes |
Application | sun | jdk | 1.1.0 | Yes |
Application | sun | jdk | 1.1.6 | Yes |
Application | sun | jdk | 1.1.6 | Yes |
Application | sun | jdk | 1.1.7b | Yes |
Application | sun | jdk | 1.1.7b | Yes |
Application | sun | jdk | 1.1.8 | Yes |
Application | sun | jdk | 1.1.8 | Yes |
Application | sun | jdk | 1.1.8 | Yes |
Application | sun | jdk | 1.1.8 | Yes |
Application | sun | jdk | 1.1.8 | Yes |
Application | sun | jdk | 1.1.8 | Yes |
Application | sun | jdk | 1.2.0 | Yes |
Application | sun | jdk | 1.2.1 | Yes |
Application | sun | jdk | 1.2.1 | Yes |
Application | sun | jdk | 1.2.2 | Yes |
Application | sun | jdk | 1.2.2 | Yes |
Application | sun | jdk | 1.3.0 | Yes |
Application | sun | jdk | 1.3.0_01 | Yes |
Application | sun | jdk | 1.3.0_02 | Yes |
Application | sun | jdk | 1.3.0_03 | Yes |
Application | sun | jdk | 1.3.0_04 | Yes |
Application | sun | jdk | 1.3.0_05 | Yes |
Application | sun | jdk | 1.3.1 | Yes |
Application | sun | jdk | 1.3.1 | Yes |
Application | sun | jdk | 1.3.1 | Yes |
Application | sun | jdk | 1.3.1_01 | Yes |
Application | sun | jdk | 1.3.1_01a | Yes |
Application | sun | jdk | 1.3.1_02 | Yes |
Application | sun | jdk | 1.3.1_03 | Yes |
Application | sun | jdk | 1.3.1_04 | Yes |
Application | sun | jdk | 1.3.1_05 | Yes |
Application | sun | jdk | 1.3.1_06 | Yes |
Application | sun | jdk | 1.3.1_07 | Yes |
Application | sun | jdk | 1.3.1_08 | Yes |
Application | sun | jdk | 1.3.1_09 | Yes |
Application | sun | jdk | 1.3.1_10 | Yes |
Application | sun | jdk | 1.3.1_11 | Yes |
Application | sun | jdk | 1.3.1_12 | Yes |
Application | sun | jdk | 1.3.1_13 | Yes |
Application | sun | jdk | 1.3.1_14 | Yes |
Application | sun | jdk | 1.3.1_15 | Yes |
Application | sun | jdk | 1.3.1_16 | Yes |
Application | sun | jdk | 1.3.1_17 | Yes |
Application | sun | jdk | 1.3.1_18 | Yes |
Application | sun | jdk | 1.3.1_19 | Yes |
Application | sun | jdk | 1.3.1_20 | Yes |
Application | sun | jdk | 1.3.1_21 | Yes |
Application | sun | jdk | 1.3.1_22 | Yes |
Application | sun | jdk | 1.3.1_23 | Yes |
Application | sun | jdk | 1.3.1_24 | Yes |
Application | sun | jdk | 1.3.1_25 | Yes |
Application | sun | jdk | 1.3.1_26 | Yes |
Application | sun | jdk | 1.3.1_27 | Yes |
Application | sun | jdk | 1.3.1_28 | Yes |
Application | sun | jdk | 1.4.0 | Yes |
Application | sun | jdk | 1.4.0_01 | Yes |
Application | sun | jdk | 1.4.0_02 | Yes |
Application | sun | jdk | 1.4.0_03 | Yes |
Application | sun | jdk | 1.4.0_04 | Yes |
Application | sun | jdk | 1.4.1 | Yes |
Application | sun | jdk | 1.4.1_01 | Yes |
Application | sun | jdk | 1.4.1_02 | Yes |
Application | sun | jdk | 1.4.1_03 | Yes |
Application | sun | jdk | 1.4.1_04 | Yes |
Application | sun | jdk | 1.4.1_05 | Yes |
Application | sun | jdk | 1.4.1_06 | Yes |
Application | sun | jdk | 1.4.1_07 | Yes |
Application | sun | jdk | 1.4.2 | Yes |
Application | sun | jdk | 1.4.2_1 | Yes |
Application | sun | jdk | 1.4.2_2 | Yes |
Application | sun | jdk | 1.4.2_3 | Yes |
Application | sun | jdk | 1.4.2_4 | Yes |
Application | sun | jdk | 1.4.2_5 | Yes |
Application | sun | jdk | 1.4.2_6 | Yes |
Application | sun | jdk | 1.4.2_7 | Yes |
Application | sun | jdk | 1.4.2_8 | Yes |
Application | sun | jdk | 1.4.2_9 | Yes |
Application | sun | jdk | 1.4.2_10 | Yes |
Application | sun | jdk | 1.4.2_11 | Yes |
Application | sun | jdk | 1.4.2_12 | Yes |
Application | sun | jdk | 1.4.2_13 | Yes |
Application | sun | jdk | 1.4.2_14 | Yes |
Application | sun | jdk | 1.4.2_15 | Yes |
Application | sun | jdk | 1.4.2_16 | Yes |
Application | sun | jdk | 1.4.2_17 | Yes |
Application | sun | jdk | 1.4.2_18 | Yes |
Application | sun | jdk | 1.4.2_19 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0 | Yes |
Application | sun | jdk | 1.5.0_03 | Yes |
Application | sun | jdk | 1.5.0_03 | Yes |
Application | springsource | dm_server | 1.0.0 | No |
Application | springsource | dm_server | 1.0.1 | No |
Application | springsource | dm_server | 1.0.2 | No |
Application | springsource | spring_framework | 1.1.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0 | No |
Application | springsource | spring_framework | 2.0.1 | No |
Application | springsource | spring_framework | 2.0.2 | No |
Application | springsource | spring_framework | 2.0.3 | No |
Application | springsource | spring_framework | 2.0.4 | No |
Application | springsource | spring_framework | 2.0.5 | No |
Application | springsource | spring_framework | 2.1 | No |
Application | springsource | spring_framework | 2.1 | No |
Application | springsource | spring_framework | 2.1 | No |
Application | springsource | spring_framework | 2.1 | No |
Application | springsource | spring_framework | 2.5.0 | No |
Application | springsource | spring_framework | 2.5.0 | No |
Application | springsource | spring_framework | 2.5.0 | No |
Application | springsource | spring_framework | 2.5.1 | No |
Application | springsource | spring_framework | 2.5.2 | No |
Application | springsource | spring_framework | 2.5.3 | No |
Application | springsource | spring_framework | 2.5.4 | No |
Application | springsource | spring_framework | 2.5.5 | No |
Application | springsource | spring_framework | 2.5.6 | No |
Application | springsource | spring_framework | 3.0.0 | No |
Application | springsource | spring_framework | 3.0.0 | No |